Skip to main content

Version 3.6.2

Initial release

June 5, 2026

Release Type

Stable – Incremental Feature Release


Summary

Version 3.6.2 lands a new Accessories module that finally tracks the chargers, cases, styluses, and cables that ship out alongside your devices — issued individually or bundled with a checkout, with replacement-threshold warnings when the same charger gets handed to the same student one too many times.

A second major area of investment is sign-in. Microsoft 365 (Entra ID) joins Google as a zero-configuration sign-in option, ClassLink LaunchPad is now wired through a central-proxy multi-tenant flow that just works for every district, and the Admin SSO Settings page has been redesigned around brand-coloured identity provider rows with a Force-SSO master toggle.

The User Portal has grown: students and staff get a My Checkouts page with current devices and full handoff history, a Pre-Issuance Review readout that surfaces missing fields and recent logins on the admin user profile, and a refreshed ticket-entry picker that handles cart slots, cart-level tickets, permanently attached devices, and rooms a teacher is responsible for.

Plus a configurable Pre-Issuance Review with audience-scoped checks, OneRoster custom-field metadata mapping that lets SIS-side metadata values (bus route, graduation year, cohort, etc.) flow straight onto a Manage1to1 user custom field, a mergefield catalog for Smart Rules notifications, a hardened CSV export pipeline that no longer paints an HTML error page over your file, and customizable password generation.

Marquee features:

Plus a CSV-export hardening pass, password-manager autocomplete suppression site-wide in /admin, an improved import pipeline that tolerates duplicate columns and classic-Mac line endings, and a round of bug fixes including a critical fix for the Device-Full export 500 and the Dashboard Recent Devices widget.


New Features

Accessories Module

The new Accessories module gives chargers, styluses, hard cases, screen protectors, USB-C cables, and headphones their own dedicated home — separate from Parts Inventory (which is for internal repair components). You define your district's accessory catalog, track stock at each location, and issue accessories to users — either on their own or bundled with a device checkout.

Catalog & Inventory

  • A district-wide catalog of accessory types (Charger, Stylus, Hard Case, etc.) — each with a name, SKU, default cost, description, and an active / deactivated flag
  • Per-location on-hand counts that share the same inventory locations as Parts (one location per warehouse / tech office)
  • Adjust Stock for received shipments or damaged-on-arrival write-offs, Transfer between locations with a reason, and a full recent-transfers history per accessory

Per-User Issuance

  • An Accessories card on every user profile lives between Current Checkouts and Current Incidents
  • Issue an accessory inline: pick from the catalog dropdown, choose the source location, set status to Accepted or Declined (refusals still record for audit but don't decrement stock)
  • Optional "Don't decrement stock for this issuance" checkbox for paper-trail-only entries
  • Every accepted row has an inline Mark Lost action that flips status without auto-issuing a replacement; can be reversed with Mark Found if it turns up

Bundle With a Checkout

  • When a device gets checked out, the Bundle Accessories modal opens automatically against the new lease
  • Scan a barcode (or type a SKU) to auto-tick the matching accessory row, or click checkboxes manually
  • Per-row "From Location" so a charger from Central Warehouse and a case from the tech office can ride one bundle
  • Bundled accessories show up grouped under the device's asset tag on the user profile, and listed on the device profile's new Accessories on This Device card

Check-In Handoff

  • After a standard check-in, a yellow banner appears on the user profile if accessories from that lease are still active
  • Process Handoff opens a page with the active accessories and three decision buttons per row: Returned (closes assignment, restocks the source location), Keep (user keeps it, row stays open but un-nests from the device), Lost (stamps loss timestamp, no stock change)
  • Mixed decisions are normal — return the case, keep the stylus, mark the charger lost in one save

Replacement-Threshold Warning

  • When a user has been issued the same accessory 3 times in the trailing 12 months (bundled or standalone, lost or not), a yellow banner appears on their Accessories card
  • The threshold is per-district configurable via the AccessoryReplacementWarningThreshold setting in Settings → Configure General Settings — set higher to relax, set to 0 to disable entirely

Documentation: Accessories Overview · Bundling Accessories With a Checkout · Issuing, Losing, and Replacing an Accessory


Sign-In Overhaul

3.6.2 overhauls the Single Sign-On experience on three fronts at once.

Microsoft 365 (Entra ID) SSO — A new Sign in with Microsoft option appears on the admin login page and User Portal sign-in page out of the box. Works with any Microsoft 365 / Entra ID tenant — typical for districts running Microsoft school environments. Same zero-config story as Google: no app registration on the district side, no API keys to paste, no admin consent setup required for individual users. Personal Microsoft accounts (@outlook.com, @hotmail.com, Xbox / Skype) are correctly rejected — only work and school accounts issued by an Entra tenant are accepted.

ClassLink Multi-Tenant Rewrite — ClassLink SSO is now wired through a Manage1to1-hosted central proxy so every district works with no per-district ClassLink app to register, no client IDs to copy, and no domain-allowlist round-trips. Users click Sign in with ClassLink, authenticate against their district's LaunchPad, and land back at Manage1to1 already signed in.

Admin SSO Settings Redesign — The Settings → SSO Settings page has been rebuilt around a clean per-provider row layout with brand-coloured identity-provider chips (Google blue, Microsoft cyan, ClassLink navy) and No Configuration Required badges so you can see at a glance which providers are zero-setup. A new Force Single Sign-On master toggle at the top of the page hides the password sign-in form entirely once you've verified at least one provider works end-to-end for your admins — useful for districts standardising on centralised identity.

Documentation: SSO Settings · Enabling Single Sign-On for Your District


Pre-Issuance Review

A new Pre-Issuance Review panel sits in the left column of every user profile — designed for techs who want to confirm a student or staff member is set up correctly before issuing hardware, without hunting through tabs.

The panel shows two things at a glance:

  • Profile — a Complete / Incomplete indicator driven by checks your district has enabled. Hover to see exactly which check is failing.
  • Recent Logins — the five most recent times this user signed in to the User Portal, with date / time, sign-in method (Password, Google SSO, Microsoft 365 SSO, ClassLink SSO, or Magic Link), and source IP. Useful when a user says "I can't log in" — quickly tells you whether they ever have.

Configurable checks — the new Settings → Pre-Issuance Review page lets you choose which user-profile fields count toward Complete: Email address, Username, Building assigned, Grade assigned (students only), Guardian email (students only), Guardian phone (students only). Audience-scoped checks automatically skip the opposite role, so a staff record won't show Incomplete just because there's no guardian email on file.

The default check set (Email + Username + Building) is the historic baseline; districts that need parent-comm coverage typically also enable Guardian email.

Documentation: User Profile — Pre-Issuance Review Panel · Pre-Issuance Review Settings


OneRoster Custom-Field Metadata Mapping

User custom fields can now be bound to a OneRoster metadata key so SIS-driven values flow into Manage1to1 automatically.

OneRoster lets your SIS attach district-specific metadata values to each user — typical examples are bus route, graduation year, cohort, and program track. When you create a user custom field, the new OneRoster Metadata Key input binds the field to one of those keys. Every subsequent OneRoster sync writes the SIS value onto every matching student's profile — no manual entry needed.

  • Bound fields are SIS-owned — the OneRoster sync overwrites any manual edits on the next tick, so leave the Metadata Key blank if you want a manually-maintained field
  • The key must start with a letter and contain only letters, digits, and underscores
  • Unbound fields keep working as before — this is opt-in per field, not a global switch

Documentation: Custom Fields Tab — OneRoster Metadata Key · Mapping SIS Data into User Custom Fields


User Portal Expansion

The User Portal grew substantially in 3.6.2.

My Checkouts — A new dedicated page on the student / staff portal shows the user's current devices (with serial, asset tag, building, condition notes, and checkout date) and their full handoff history (every device they've ever had, when they got it, when they returned it). Gives students and parents a clear self-service view without contacting IT.

Cart-Slot Ticket Picker — When a student opens the ticket-entry form and they're on a cart-based lease, the picker drills into the cart so they can specify which slot / which device they're reporting an issue with — instead of just "the cart". The submitted ticket carries the specific slot + serial so the tech doesn't have to guess.

Cart-Itself Option — For tickets about the cart's hub, lid, missing keys, etc. (rather than a specific Chromebook on the cart), the picker now offers a "The cart itself" option that records the ticket against the cart_lease rather than any individual device.

Permanently Attached Devices — Devices that are fixtures inside a cart (charging hubs, locks, sensors) now appear in the ticket picker for the teacher who has the cart checked out, even though those devices don't have leases of their own.

Rooms You Manage — If a teacher is responsible for a room, the devices in that room (ViewSonic boards, cameras, etc.) appear in the picker too, even without an individual lease.

Submitter IP on Tickets — Tickets and end-user replies submitted via the User Portal now display the submitter's IP address on the admin-side ticket profile, useful for triage and security investigations.

Expanded Documentation — The User Portal docs section now covers Signing In, Dashboard, My Tickets, My Checkouts, Knowledge Base / Help Center, Your Profile, and Parent Portal (including AUP signing) as dedicated pages.

Documentation: User Portal · Submitting Tickets From the User Portal


Lost Device Flow Polish

Marking a device lost is now more nuanced:

  • Keep on profile — by default, marking a device lost keeps the lease open so the device stays visible on the user's profile. Tick Also end this checkout in the mark-lost modal if you want to close the lease at the same time (the legacy behaviour).
  • Lost-accessory tracking — a free-text notes field on the mark-lost flow captures what accessories went missing along with the device (e.g. "charger, stylus"), surfaced on the user profile next to the Lost badge.
  • Handoff jump for bundled accessories — if the lost device's lease has active bundled accessories, marking the device lost takes you straight to the Accessory Handoff page so you can decide per-accessory whether each is Returned, Kept by the user, or also Lost.

Documentation: Marking Devices Lost


Smart Rules Mergefield Catalog

Smart Rules Notify admin(s) by email actions now support a documented catalog of merge fields you can drop into the subject and body of the notification.

  • Incident-target rules get 17 tokens: {$incident_id}, {$incident_date}, {$incident_status}, {$incident_completed_date}, {$incident_assessment}, {$incident_repair}, {$incident_url}, {$fullname}, {$first_name}, {$last_name}, {$email}, {$grade}, {$school}, {$building}, {$device_serial}, {$device_barcode}, {$device_model}
  • Device-target rules get 11 tokens: {$device_id}, {$device_serial}, {$device_barcode}, {$device_model}, {$device_status}, {$device_url}, {$building}, {$assigned_to_fullname}, {$assigned_to_first_name}, {$assigned_to_last_name}, {$assigned_to_email}
  • An Available merge fields collapsible block appears under the body textarea on the rule edit page, listing every token with what it expands to — no guessing
  • Unknown tokens stay literal in the rendered email so typos are visible instead of silently dropped

Documentation: Smart Rules — Merge fields in the notification subject and body


Customizable Password Generation

Districts can now control the rules used when Manage1to1 generates a password — for new user creation, password resets, and the admin password generator on the user profile.

  • Configure password length, character classes (uppercase, lowercase, digits, symbols), and complexity requirements
  • The same rules drive every password the system generates, so generated passwords always meet district policy

Documentation: Password Generation Rules


Configurable Pre-Issuance Review Checks

(See Pre-Issuance Review above — the configuration UI ships in 3.6.2 alongside the panel itself.)


Accessory-Lost Flag on Lost-Device Flow

(See Lost Device Flow Polish above.)


Warehouse Receive Transfer — Signature Capture

Receiving a warehouse-to-campus transfer now captures a digital signature at the campus end, completing the audit trail that the warehouse-side signature started.


Parts Check-Out — Transfer to New Location

The parts check-out flow can now transfer a part to a different location at check-out time, with quantity and reason captured. Useful for tech-to-tech part hand-offs that previously required two separate transfer steps.


Improvements

Accessories Polish Pass

Layout, spacing, and theme handling across the Accessories module got a comprehensive cleanup. The user-profile accessory card now reads cleanly in both light and dark themes, and stock-count badges use theme-neutral styling so they stay legible regardless of theme.

Accessories Scan-to-Issue + Standardized Picker Styling

The Issue Accessory modal now accepts a scanned barcode or typed SKU to auto-select the catalog entry. The Select-style dropdowns used across admin forms have been standardised so every picker looks and behaves the same.

Admin Password-Manager Autocomplete Suppression

Browser password managers (LastPass, 1Password, Bitwarden, native browser autofill) are now suppressed across the admin area — except on the login page (where they're expected) and My Profile (where staff change their own password). Stops the common "browser autofilled my district email into the wrong field" failure mode when an admin is editing another user's record.

Apple School Manager AppleCare — Rate-Limit Throttling + Quieter Activity Log

AppleCare coverage lookups against Apple School Manager are now throttled to stay within Apple's published rate limits — important for larger districts whose sync volume previously tripped throttling mid-run. The debug stream those lookups produce has also been moved out of the user-visible Activity Log so it no longer crowds out real activity entries.


Bug Fixes

  • MAN-1164 — Resolved an issue where the Device Full export could fail to complete and produce an unusable file. Both the manual and scheduled exports now run to completion reliably.

  • MAN-1124 — Resolved an issue where the Recent Devices dashboard widget could fail to render. The widget now loads reliably.

  • MAN-1131 — Imports that contained duplicate column names in the header row previously appeared to succeed without writing any rows. The importer now surfaces the duplicate-column condition clearly and aborts the import so the file can be corrected and re-uploaded.

  • MAN-1132 — Student / Staff imports saved on older Mac systems were treated as a single row, and any unknown header columns were silently ignored. Both behaviours are fixed: line endings are normalised before parsing, and unknown columns now surface as a warning so they aren't missed.

  • MAN-1134 — Incident profiles could occasionally surface the wrong insurance policy for devices that had been covered by multiple policies over time. The policy shown is now the one active on the incident date.

  • MAN-1176 — If an export ran into an error part-way through, the error page itself could end up inside the downloaded file. Exports that hit an error now produce a clean truncated file with a short error indicator instead.

  • MAN-1175 — Tokens like {$incident_id} and {$fullname} in the Smart Rules Notify admin(s) by email subject and body previously rendered as literal text. They now resolve correctly — see Smart Rules Mergefield Catalog for the full list.

  • MAN-1174 — Resolved an issue where the Lost Device Report could return an error. The report now loads reliably.

  • MAN-1159 — Resolved an issue where the Parts Transfers and Parts Adjustments tables could fail to load. Both tables now populate reliably.

  • MAN-1163 — Resolved an intermittent error in the Sign in with Google callback. The round-trip now completes reliably.

  • MAN-1165 — Editing a device and changing only custom-field values previously didn't persist. Custom field changes are now saved correctly whether or not core device fields changed.

  • MAN-1129 — Districts on a non-UTC time zone could appear stale on the Cron Status page even when cron was running normally. Time zone handling is fixed.

  • MAN-1138 — The Scheduled Reports cron previously wrote activity-log rows on every tick whether or not it had work to do. It now only logs when work runs.

  • MAN-1156 — Activity-log rows recorded during a system update could be attributed to the user who happened to trigger the update. They are now attributed to System consistently.

  • MAN-1118 — A district saw clearly impossible Google MDM sync counts and storage figures. Aggregation is fixed.

  • MAN-1119 — The Campus Summary widget could show wrong totals for buildings that had been renamed mid-year. Totals are now correct after a rename.

  • MAN-1123 — Resolved a favicon load failure on the admin and client-area pages.


Notes for This Release

  • No breaking API changes — every external API endpoint behaves identically.
  • Rolling out Force SSO? If you're switching your district to SSO-only sign-in with this release, see the Enabling Single Sign-On guide for the recommended verification + communication sequence before flipping the master toggle.

Changelog

TypeIssueDescription
NEW FEATUREMAN-1143Accessories module: catalog, inventory, per-user issuance, replacement-threshold warning
NEW FEATUREMAN-1173Bundle accessories with a device checkout + check-in handoff page
NEW FEATUREMAN-1170Accessory scan-to-issue + standardized Select2 picker helper
NEW FEATUREMAN-1166Microsoft 365 (Entra ID) Single Sign-On — zero configuration
NEW FEATUREMAN-1167ClassLink Single Sign-On — central-proxy multi-tenant rewrite
NEW FEATUREMAN-1142Pre-Issuance Review panel on user profile (Profile + Recent Logins)
NEW FEATUREMAN-1171OneRoster metadata key binding on user custom fields
NEW FEATUREMAN-1153User Portal — My Checkouts page (current devices + handoff history)
NEW FEATUREMAN-1148User Portal ticket entry — cart-slot picker + "the cart itself" option
NEW FEATUREMAN-1155User Portal ticket entry — permanently attached devices + Rooms You Manage
NEW FEATUREMAN-1154Submitter IP on tickets and end-user replies (admin-side)
NEW FEATUREMAN-1145Lost Device flow — keep on profile, accessories-lost tracking
NEW FEATUREMAN-1151Lost Device flow — jump to Accessory Handoff page
NEW FEATUREMAN-1141E-signature capture on warehouse-to-campus transfer receipt
NEW FEATUREMAN-1147Parts check-out — transfer to a new location with quantity + reason
NEW FEATUREMAN-457Customizable password generation rules
NEW FEATUREMAN-1160Warehouse receive-transfer signature capture
IMPROVEMENTMAN-1172Per-district configurable Pre-Issuance Review checks
IMPROVEMENTMAN-1168Admin SSO Settings page redesign + brand-color identity buttons
IMPROVEMENTMAN-1169Accessories module visual polish pass
IMPROVEMENTMAN-1122Suppress password-manager autocomplete site-wide in /admin
IMPROVEMENTMAN-1125Throttle AppleCare coverage lookups within Apple School Manager rate limits
IMPROVEMENTMAN-1130Move ASM AppleCare debug logging out of the Activity Log
IMPROVEMENTMAN-1135Suppress upstream advisory noise on dependencies we've audited
IMPROVEMENTMAN-1139Enrich cron run-log error payload for faster operator triage
BUG FIXMAN-1164Device-full export failing on download
BUG FIXMAN-1124Dashboard Recent Devices widget could fail to load
BUG FIXMAN-1131Student import silent failure on duplicate column names
BUG FIXMAN-1132Student/Staff import on older Mac line endings
BUG FIXMAN-1134Wrong device insurance shown on incident profile
BUG FIXMAN-1176Export error page captured into downloaded file
BUG FIXMAN-1175Smart Rules notification merge fields rendered as literal text
BUG FIXMAN-1174Lost Device Report error on load
BUG FIXMAN-1159Parts Transfers and Adjustments tables not loading
BUG FIXMAN-1163Sign in with Google occasional callback error
BUG FIXMAN-1165Device edit custom-field-only changes not saving
BUG FIXMAN-1129Cron Status page Central-time-zone tenants flagged stale
BUG FIXMAN-1138Scheduled Reports extra activity-log rows on idle ticks
BUG FIXMAN-1156System updates wrong attribution in Activity Log
BUG FIXMAN-1118Google MDM sync statistics clearly wrong
BUG FIXMAN-1119Campus Summary widget incorrect totals after building rename
BUG FIXMAN-1123Favicon 404 on admin and client-area pages
BUG FIXMAN-1162Lost-Device demo seed referenced an unknown column
TASKMAN-1150Demo seed-data realism pass (internal)
TASKMAN-1152Consolidate client-area SSO providers behind ClassLink rewrite
TASKMAN-1149Expand User Portal documentation
TASKMAN-1177StatusPage.io embed on admin login + admin chrome